OpenVSX Registry Verified

MyFlicker 2(Beta)

4850cf2d-14a3-5a89-b771-6f1c82662dc7 | v1.0.2609150
63/ 100
MEDIUM risk
Risk verdict
Review before use

Score-based assessment (medium risk, 63/100). No analyst review available.

Analysis record

Analysed
3 days ago
Version
v1.0.2609150
Artifact
SHA256 7BD…17C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 30 · highest severity first

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 27
dist/webview/assets/shellscript-Yzrsuije.jsdist/webview/assets/catppuccin-frappe-DFWUc33u.jsindex.js +24 more
-
LOWpostinstall persistence mechanism 46
dist/webview/assets/astro-HNnZUWAn.jsdist/webview/assets/twig-CW1WmMYd.jsdist/webview/assets/logo-BtOb2qkB.js +43 more
-
LOWpostinstall file download 125
dist/webview/assets/coffee-Ch7k5sss.jsdist/webview/assets/feedback-BTnCkJr7.jsdist/webview/assets/fennel-BYunw83y.js +122 more
-
LOWNoUseWeakRandom 11
dist/webview/assets/blockDiagram-GPEHLZMM-qYhlfy0A.jsdist/webview/assets/index-XdRiRph7.jsdist/webview/assets/app-LMEcWSva.js +8 more
-
LOWcredential git credentials 1
dist/webview/assets/mdx-Cmh6b_Ma.js
-
LOWSQLInjection 2
dist/webview/assets/index-XdRiRph7.jsdist/webview/assets/index-BWAEB-xR.js
-
LOWLocalStorageShouldNotBeUsed 2
dist/webview/assets/index-XdRiRph7.jsdist/webview/assets/app-LMEcWSva.js
-
LOWDebuggerStatementsShouldNotBeUsed 15
dist/webview/assets/tsx-COt5Ahok.jsdist/webview/assets/typescript-BPQ3VLAy.jsdist/webview/assets/common-lisp-Cg-RD9OK.js +12 more
-
LOWpostinstall environment access 740
dist/webview/assets/index-ndxsAoxP.jsdist/webview/assets/index-BUf1QjXE.jsdist/webview/assets/index-hkS48-cd.js +737 more
-
LOWpostinstall system command 1
dist/webview/assets/index-BjDq3fkX.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,378 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

kuaishou

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

8
Network
1,378
IoC Indicators

YARA Rules Matched

10 rules(970 hits)
credential env files postinstall persistence mechanism postinstall file download NoUseWeakRandom credential git credentials SQLInjection LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed postinstall environment access postinstall system command

Security Analysis Summary

Security Analysis Overview

MyFlicker 2(Beta) is a OpenVSX Registry extension published by kuaishou. Version 1.0.2609150 has been analyzed by the Risky Plugins security platform, receiving a risk score of 62.83/100 (MEDIUM risk) based on 5750 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 1386 finding(s)
  • Low: 4364 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

MyFlicker 2(Beta) is published by kuaishou on the OpenVSX Registry marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

MyFlicker Code Agent — VS Code Extension

Frequently Asked Questions